作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2011, Vol. 37 ›› Issue (10): 108-110. doi: 10.3969/j.issn.1000-3428.2011.10.036

• 安全技术 • 上一篇    下一篇

虚拟密码设备系统的设计与实现

祝颖泓 1,2,沈备军 1,金 波 2   

  1. (1. 上海交通大学软件学院,上海 200240;2. 公安部第三研究所信息网络安全公安部重点实验室,上海 201204)
  • 出版日期:2011-05-20 发布日期:2011-05-20
  • 作者简介:祝颖泓(1987-),女,硕士研究生,主研方向:虚拟计算,信息安全;沈备军,副教授、博士;金 波,研究员、博士
  • 基金资助:
    国家“863”计划基金资助项目(2008AA01Z412)

Design and Implementation of Virtual Cryptographic Device System

ZHU Ying-hong 1,2, SHEN Bei-jun 1, JIN Bo 2   

  1. (1. School of Software, Shanghai Jiaotong University, Shanghai 200240, China; 2. Key Laboratory of Information Network Security, Ministry of Public Security,Third Institute of Ministry of Public Security, Shanghai 201204, China)
  • Online:2011-05-20 Published:2011-05-20

摘要: 虚拟机在虚拟化环境下代替本地终端直接与应用服务器交互,但在使用本地密码设备时虚拟硬件不支持密码设备的接口。针对上述问题,提出将虚拟密码设备系统(VCDS)作为中间方连接本地终端的真实密码设备和虚拟终端应用层的方案。给出VCDS各核心模块的设计和实现,对系统进行安全性分析,证明其有助于保证虚拟终端透明地使用本地真实密码设备,提供良好的加密认证等安全服务。

关键词: 虚拟桌面, 密码设备, 安全服务, 本地终端, 虚拟终端

Abstract: Virtual machine, instead of the local terminal, communicates with application server in virtual environment. However, the virtual hardware may not support the interface of the cryptographic device when virtual machine uses the local cryptographic device. This paper proposes to develop Virtual Cryptographic Device System(VCDS) as the intermediate party, which combines the real cryptographic device plugged into the local terminal and the application layer of virtual terminal. It describes the designs of the core modules, as well as the implementations of VCDS, and analyzes its security. This system helps to ensure the transparency when virtual terminal using local real cryptographic device, and provides a good service of encryption, authentication and so on.

Key words: virtual desktop, cryptographic device, security service, local terminal, virtual terminal

中图分类号: